sync: detect orphaned blobs (pepper rotation) + fix AESGCM arg order
Adds an 8-byte HKDF fingerprint of the current pepper to portfolio_sync rows. On fetch, a mismatch surfaces as 410 Gone (distinct from genuine GCM corruption → 500), and the UI silently cleans up the dead row and shows a soft "please re-import" notice instead of a confusing PIN re-prompt. Legacy rows (pepper_fp NULL) are probed optimistically and backfilled on success. Also fixes a latent bug in unwrap(): AESGCM.decrypt args were swapped (ct, nonce instead of nonce, ct), so restore-from-cloud always failed even when the pepper was correct. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
parent
f1903e1e61
commit
5c7cc4c6aa
8 changed files with 224 additions and 18 deletions
|
|
@ -256,7 +256,18 @@
|
|||
}
|
||||
const valueEl = statusEl.querySelector('.settings-row__value');
|
||||
actionsEl.innerHTML = '';
|
||||
if (status.exists) {
|
||||
if (status.exists && status.orphaned) {
|
||||
// The stored blob can no longer be decrypted (server key rotated
|
||||
// since it was written). The data is permanently unrecoverable,
|
||||
// so silently clean up the dead row and re-render in the
|
||||
// standard "off" state — leaving a soft one-liner so the user
|
||||
// knows why they need to re-import.
|
||||
try { await window.CassandraSync.disableSync(); }
|
||||
catch (e) { console.warn('auto-clear stale sync failed', e); }
|
||||
setFeedback('Your previous cloud backup couldn’t be restored. Re-import your portfolio to enable cloud sync again.', true);
|
||||
await refresh();
|
||||
return;
|
||||
} else if (status.exists) {
|
||||
const when = status.updated_at
|
||||
? new Date(status.updated_at).toISOString().replace('T', ' ').slice(0, 16) + ' UTC'
|
||||
: '—';
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue